Reply to post: Conclusion

Time for a patch: six vulns fixed in NTP daemon

Anonymous Coward
Anonymous Coward

Conclusion

Please correct me if I'm wrong here.

Most of these vulnerabilities require ntpd's authentication scheme(s) to be configured, which are horribly fragile by themselves and practically never used outside self-hopping minefields.

That leaves the Xleave problem, although having multiple server associations might protect a little.

Well, auto-update should take care of most of our servers. Only the custom ntpd on a Raspberry Pi w/ GPS needs recompiling.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon